Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Vulnerability Fix Time Increases by 47%

February 28, 2025
Reading Time: 2 mins read
in Incidents
LockBit Targets New FBI Director Kash Patel

Veracode’s latest State of Software Security (SoSS) report reveals concerning trends in software security vulnerabilities. The average time to fix these vulnerabilities has significantly increased, rising to eight and a half months, which marks a 47% rise over the past five years. This is a drastic change compared to 15 years ago, where the fix time was 327% lower. The report attributes much of this delay to the growing dependence on third-party code and the rise of AI-generated code, which have made software ecosystems more complex and difficult to secure.

A significant portion of the security challenges organizations face is the accumulation of critical security debt.

The report indicates that 50% of all organizations have vulnerabilities that have been left unresolved for over a year, with critical vulnerabilities accounting for 70% of this debt. These critical flaws often come from third-party code, highlighting the risk associated with software supply chains. Despite efforts to improve security, the prevalence of security debt remains high, with 74.2% of organizations facing some form of security debt, ranging from high-severity flaws to more minor issues.

The analysis also highlights stark differences in how various organizations manage security flaws.

The top 25% of organizations are able to fix more than 10% of their software flaws every month, whereas the bottom 25% address less than 1%. The report also points out that the most mature organizations have security debt in only 17% of their applications, while the least mature organizations carry this burden in over 67% of their applications. This disparity shows the varying levels of maturity in handling vulnerabilities across the industry.

Despite these alarming figures, there are some positive trends. The number of applications free from flaws listed in the OWASP Top 10 vulnerabilities has increased by 63% over the past five years. Furthermore, the prevalence of high-severity flaws has been halved since 2016, demonstrating gradual improvements in security practices. However, with over half of applications still containing critical vulnerabilities, there is clearly much work to be done to address the growing security challenges in today’s software environments.

Reference:

  • Average Fix Time for Software Vulnerabilities Increases by 47% in 5 Years
Tags: cyber incidentsCyber Incidents 2025Cyber threatsFebruary 2025
ADVERTISEMENT

Related Posts

Tiffany & Co. Faces Data Breach Incident

Migos IG Hack Blackmails Solana Cofounder

May 28, 2025
Tiffany & Co. Faces Data Breach Incident

Tiffany & Co. Faces Data Breach Incident

May 28, 2025
Tiffany & Co. Faces Data Breach Incident

MathWorks Crippled by Ransomware Attack

May 28, 2025
Semiconductor Firm AXT Hit by Data Breach

Adidas Data Breach Exposes Customer Contacts

May 27, 2025
Everest Ransomware Leaks Coke Staff Data

Everest Ransomware Leaks Coke Staff Data

May 27, 2025
Semiconductor Firm AXT Hit by Data Breach

Semiconductor Firm AXT Hit by Data Breach

May 27, 2025

Latest Alerts

Microsoft Void Blizzard Cyber Threat Alert

Fake DocuSign Alerts Target Corporate Logins

Fake Bitdefender Site Spreads Venom Malware

FBI Warns Luna Moth Targets US Law Firms

Winos 4.0 Malware Spread Via Fake Installers

GhostSpy Android Malware Full Device Control

Subscribe to our newsletter

    Latest Incidents

    Migos IG Hack Blackmails Solana Cofounder

    Tiffany & Co. Faces Data Breach Incident

    MathWorks Crippled by Ransomware Attack

    Everest Ransomware Leaks Coke Staff Data

    Adidas Data Breach Exposes Customer Contacts

    Semiconductor Firm AXT Hit by Data Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial